A practical guide for organisations deploying AI in Europe, the UK, Ireland, and the US.
Published: May 2026 | 5–8 min read | Keywords: DPIA, FRIA, GDPR Art. 35, AI Act Art. 27, Fundamental Rights Impact Assessment, Data Protection Impact Assessment, High-Risk AI, EU AI Act Compliance, AI Governance, Responsible AI
The EU AI Act is now in force. For organisations deploying artificial intelligence, this means a new legal obligation sits alongside the familiar GDPR: the Fundamental Rights Impact Assessment (FRIA) under Article 27. Many compliance teams assume their existing Data Protection Impact Assessment (DPIA) covers both. It does not. When high-risk AI processes personal data, both assessments are legally required — simultaneously.
This post explains the difference, when each applies, and how to run them together efficiently.
Executive Summary
Organisations deploying AI in Europe increasingly need to assess both data protection risks and broader fundamental rights impacts. While a Data Protection Impact Assessment (DPIA) under GDPR Article 35 focuses on risks arising from personal data processing, a Fundamental Rights Impact Assessment (FRIA) under Article 27 of the EU AI Act evaluates the wider impact of high-risk AI systems on fundamental rights such as equality, non-discrimination, human dignity, and access to justice.
Many organisations assume that an existing DPIA satisfies AI Act requirements. In most cases, it does not. Where a high-risk AI system listed in Annex III of the EU AI Act also processes personal data at high risk, both assessments are typically required.
This guide explains the differences between DPIAs and FRIAs, when each applies, and how organisations can efficiently manage both obligations within a unified AI governance framework.
Key Definitions
1. The DPIA — GDPR Article 35
What it is: A structured risk assessment of personal data processing operations that are likely to result in high risk to individuals’ rights and freedoms.
When it is required:
- Systematic profiling or automated decision-making with significant effects on individuals
- Large-scale processing of special category data (health, biometric, genetic, etc.)
- Systematic monitoring of publicly accessible areas
- Any processing flagged as high-risk by your national Data Protection Authority (DPA)
What it must cover (Art. 35(7) GDPR):
- Description of the processing and its purpose
- Assessment of necessity and proportionality
- Risk assessment to data subjects’ rights and freedoms
- Measures to address identified risks
Who owns it: The Data Controller. The DPO must be consulted. If high residual risk remains, prior consultation with the DPA (Art. 36 GDPR) is mandatory before processing begins.
Applies to AI? Yes — any AI system that processes personal data at high risk triggers a DPIA independently of the AI Act.
2. The FRIA — EU AI Act Article 27
What it is: An impact assessment of deploying a high-risk AI system on the full spectrum of EU fundamental rights — going well beyond privacy and data protection.
When it is required: When deploying an AI system listed in Annex III of the EU AI Act, including:
- Biometric identification and categorisation systems
- AI in employment, recruitment, and worker management
- AI in education and vocational training
- Credit scoring and access to essential services
- Law enforcement, migration, border control
- Administration of justice and democratic processes
What it must cover (beyond privacy):Human dignity and non-discrimination (algorithmic bias)
- Equality and vulnerable group impacts (children, minorities, persons with disabilities)
- Freedom of expression, assembly, and access to justice
- Workers’ rights in AI-assisted employment decisions
Who owns it: The Deployer of the AI system — not the provider/developer. Public-sector deployers must register a FRIA summary in the EU AI Act database. Private-sector deployers maintain it internally.
Key distinction: The FRIA covers group and societal impacts, not just individual data subjects — a broader lens than GDPR allows.
3. Side-by-Side: DPIA vs FRIA
| Dimension | DPIA — GDPR Art. 35 | FRIA — AI Act Art. 27 |
| Legal Basis | GDPR Article 35 | EU AI Act Article 27 + Annex III |
| Owned by | Data Controller | Deployer of the AI system |
| Focus | Personal data risks to individuals | Fundamental rights impacts (broader: dignity, equality, access to justice, privacy, and more) |
| Trigger | High-risk data processing (profiling, sensitive data, systematic monitoring) | Deploying a high-risk AI system listed in Annex III |
| Timing | Before processing begins | Before deployment |
| Public disclosure | Internal — DPA consultation if risk remains high | Public sector: EU database registration. Private sector: internal record |
| Fines (max) | €10M or 2% global turnover | €15M or 3% global turnover |
| Overlap zone | Both apply when an Annex III AI system also processes personal data at high risk | Both apply when an Annex III AI system also processes personal data at high risk |
4. When You Need Both
Both apply when an Annex III high-risk AI system also processes personal data at high risk to individuals. In practice, most Annex III systems do exactly this. Examples:
- Recruitment AI: Annex III trigger (employment AI) + GDPR trigger (automated decisions affecting employment prospects)
- Credit scoring AI: Annex III trigger (access to financial services) + GDPR trigger (large-scale profiling)
- Biometric workplace system: Annex III trigger + GDPR trigger (sensitive biometric data processing)
| The FRIA extends to rights entirely outside GDPR’s scope (dignity, equality, access to justice, freedom of expression). Each assessment is a separate legal obligation. They can share underlying documentation — but each must be completed and maintained independently. |
5. Jurisdictional Quick Reference
EU
Both GDPR (DPIA) and the EU AI Act (FRIA) apply when their respective triggers are met. AI Act Annex III obligations for deployers apply from August 2026.
Ireland
The Data Protection Commission (DPC) oversees DPIA compliance. Irish-based multinationals are DPC-regulated. An AI supervisory authority is being designated — monitor updates from the DPC and AI Office.
United Kingdom
UK GDPR mirrors GDPR DPIA obligations (ICO oversight). The UK has not adopted the EU AI Act but sector regulators (ICO, FCA, Ofcom) are developing AI-specific guidance. UK entities with EU operations remain subject to the FRIA when deploying Annex III systems in the EU.
United States
No federal DPIA or FRIA equivalent exists, but NIST AI RMF and state-level AI laws (Colorado, Connecticut, Texas) increasingly require impact assessments. US multinationals with EU operations must comply with both the GDPR and the AI Act obligations for their European activities.
6. Next Steps: your action plan
- Classify your AI systems: Check every AI tool against Annex III. If it qualifies as high-risk and processes personal data, you need both a DPIA and an FRIA.
- Review existing DPIAs: AI deployments may now require a FRIA in addition to a DPIA already in place.
- Assign ownership: DPO leads the DPIA; a named AI governance lead should own the FRIA. Collaboration is essential.
- Build an integrated template That Shares the system description, data maps, and risk register across both assessments to avoid duplication.
- Revisit vendor contracts: If you deploy third-party AI, your contract must require the provider to share sufficient technical information to complete your FRIA.
- Set review triggers: Material changes to the AI system, new datasets, or regulatory updates should trigger simultaneous reviews of both assessments.
- Start now: FRIA obligations for Annex III deployers take effect in August 2026. Readiness assessments should begin immediately.
| Key Takeaway |
| DPIA and FRIA are complementary, not interchangeable. The DPIA protects personal data rights under GDPR. The FRIA protects the full spectrum of fundamental rights under the EU AI Act. Together, they form the foundation of responsible AI governance in Europe — and the benchmark other jurisdictions are moving towards. |
Frequently Asked Questions
How Can Symmetry Compliance Help?
At Symmetry Compliance, we support organisations across Ireland, the EU, the UK, and the US in navigating the intersection of data protection law and AI governance. Whether you are completing your first DPIA, preparing for AI Act obligations, or building an integrated governance programme, our team brings practical, regulator-ready expertise.
DPIA Support
- DPIA screening and scoping
- End-to-end DPIA delivery
- DPO advisory support
- DPA consultation support
FRIA Support
- Annex III classification reviews
- FRIA design and delivery
- Fundamental rights impact analysis
- EU AI Act compliance support
Integrated AI Governance
- Combined DPIA and FRIA frameworks
- AI governance policies and templates
- Training and awareness programmes
- Ongoing compliance monitoring
| If you would like to discuss your organisation’s DPIA or FRIA obligations, or explore how Symmetry Compliance can support your AI governance programme, contact our team at www.symmetrycompliance.ie. We work with organisations of all sizes — from scaling technology companies to established financial institutions and public bodies. |
Official References
GDPR Article 35: https://gdpr-info.eu/art-35-gdpr/
EU AI Act Article 27: https://artificialintelligenceact.eu/article/27/
EU AI Act Implementation Documents: https://artificialintelligenceact.eu/implementation-documents/
Digital Policy Alert — AI Act Art. 27 Analysis: https://clairk.digitalpolicyalert.org/chat-demo?d=738&t=0
EDPB Guidelines on DPIA (WP 248 rev.01): https://edpb.europa.eu/our-work-tools/our-documents/wp29-guidelines/guidelines-dpia-wp248_en
ICO AI & Data Protection Guidance (UK): https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/
NIST AI Risk Management Framework: https://www.nist.gov/artificial-intelligence/ai-risk-management-framework
This post is for informational purposes only and does not constitute legal advice. © Symmetry Compliance 2025.